CERT-In empanelment attaches to the testing
Security Brigade has been CERT-In empanelled since 2008. Where an instrument requires empanelled delivery, it is the testing that has to be carried out by an empanelled organisation — not only the organisation invoicing for it. That makes this a decision about which delivery model you buy, and the coverage is identical across all three.
Who can sign it
Two of the three delivery models put an auditor inside the engagement
Coverage is identical across all three. What differs is whether a Security Brigade auditor was in the engagement and can therefore sign what came out of it.
| State | What it means | What follows |
|---|---|---|
| Autonomous, expert verified | A senior Security Brigade auditor verifies every finding before any of it reaches you. The auditor is inside the engagement. | Signable under the Security Brigade empanelment. |
| Human led | A senior auditor runs the engagement with B-52 underneath — sets the scope, directs where the depth goes, and owns the report. | Signable under the Security Brigade empanelment. |
| Fully autonomous Terminal | A person authorises scope and targets and takes no further action. There is no auditor in the engagement to sign what it produced. | Built for coverage between filings. |
- An empanelled auditor is inside the engagement
- No auditor in the engagement — scope sign-off, then nothing
- TerminalNo state follows this one
Why it is a delivery decision
The distinction that decides this page
Where an instrument requires empanelled delivery, what it attaches to is the work rather than the invoice. A firm being empanelled is not the same fact as this engagement having been carried out by an empanelled auditor, and it is the second that a filing rests on. That is why the fully autonomous model — which is the fastest of the three and the one built for coverage between deep engagements — produces output for your own use rather than for a filing, and why the expert-verified model is the one to start from when the report leaves your organisation.
The instruments
Where empanelled delivery is actually written down
Each row names the instrument that carries the requirement, because they are not interchangeable and a claim scoped to the wrong one is the commonest error on this subject.
| Instrument | What it carries |
|---|---|
| SEBI CSCRF | Footnotes 16 and 17 make empanelled delivery a condition of the VAPT itself rather than only of the vendor engaged to perform it. This is the clause that makes the delivery model consequential for a regulated entity under SEBI. |
| Read 2026-09-08. | |
| PA-PG Master Direction | Payment aggregators and payment gateways: an annual system and cybersecurity audit carried out by a CERT-In empanelled auditor. |
| A Department of Payment and Settlement Systems instrument, untouched by the 31 July 2026 Department of Supervision consolidation. | |
| Storage of Payment System Data, 2018 | The System Audit Report, Board-approved and submitted to the Reserve Bank, carried out by a CERT-In empanelled auditor. |
| RBI (Commercial Banks) Directions, 2026 | Paragraph 155 requires appropriately trained and independent information security experts or auditors. Paragraph 159 addresses the case where a bank uses a CERT-In empanelled auditor: the bank is then to be guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines. |
| The guidelines referenced are CISG-2025-02 v1.0, dated 25 July 2025. The paragraph is the reason the choice matters — see the note below the table. | |
SEBI CSCRF
- What it carries
- Footnotes 16 and 17 make empanelled delivery a condition of the VAPT itself rather than only of the vendor engaged to perform it. This is the clause that makes the delivery model consequential for a regulated entity under SEBI.
Read 2026-09-08.
PA-PG Master Direction
- What it carries
- Payment aggregators and payment gateways: an annual system and cybersecurity audit carried out by a CERT-In empanelled auditor.
A Department of Payment and Settlement Systems instrument, untouched by the 31 July 2026 Department of Supervision consolidation.
Storage of Payment System Data, 2018
- What it carries
- The System Audit Report, Board-approved and submitted to the Reserve Bank, carried out by a CERT-In empanelled auditor.
RBI (Commercial Banks) Directions, 2026
- What it carries
- Paragraph 155 requires appropriately trained and independent information security experts or auditors. Paragraph 159 addresses the case where a bank uses a CERT-In empanelled auditor: the bank is then to be guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines.
The guidelines referenced are CISG-2025-02 v1.0, dated 25 July 2025. The paragraph is the reason the choice matters — see the note below the table.
What we hold
The instrument, stated precisely
Security Brigade’s CERT-In empanelment As of 2026-09-14
- Empanelled since 2008, and listed by CERT-In among the organisations it has empanelled.
- The empanelment is Security Brigade’s, as the firm delivering the engagement. B-52 is a product of Security Brigade rather than a separate company.
- It is what makes a report signable in the expert-verified and human-led delivery models, because in both an empanelled auditor is inside the engagement.
- Where a bank chooses an empanelled auditor under paragraph 159, it imports a defined audit-policy regime it is then supervised against. That is an argument for choosing one, made from what the paragraph says.
Deliberately excluded
- An empanelment is not a certification of the B-52 platform. The platform holds none, and the two are different instruments held by different parties.
- It is not a substitute for the scope agreement. What was tested is decided by the scope, and an empanelled signature on a narrow scope is a signature on a narrow scope.
How the output maps
What an engagement produces against this requirement
Testing carried out under the empanelment
In the expert-verified and human-led models the engagement has a Security Brigade auditor inside it, which is the condition an instrument requiring empanelled delivery is asking about.
A report that carries the signature
Findings, evidence, severity and remediation in one document, signed by the firm that holds the empanelment rather than referred to a third party.
A scope agreed and recorded in writing
Which targets, which classes, which roles, and what the run was authorised to do. Signed before the engagement and retained with it.
Closure, not just a finding
Each finding carries through open, fixed, retested and closed, and closes on a retest that cannot reproduce it — which is what a closure record is made of.
On paragraph 159
The honest argument for an empanelled auditor under the banking Directions
Paragraph 159 speaks to the case where a bank uses a CERT-In empanelled auditor, and says the bank is then to be guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines. Read plainly, that is an argument about what choosing an empanelled firm brings with it: a defined audit-policy regime, and a supervisory expectation the bank is measured against. It is a better reason to choose one than any claim about compulsion would be, because it survives a reader who goes and reads the paragraph. Where your obligation sits under SEBI CSCRF, the PA-PG Master Direction or the 2018 data-storage directive instead, the requirement is in the instrument itself and the table above names it.
What you receive
What the report carries for this filing
The exchange that proved it
Request and response as sent and returned, with the part that proves the defect marked, plus steps written so your own engineer can reproduce it.
Severity, with its vector
CVSS v4.0 with the vector printed, the CWE, and the framework category the finding is reported under — so a score can be recomputed rather than taken on trust.
Scope, authorisation and dates
What was in scope, who authorised it, when the testing ran, and what the three approval gates permitted or refused during it.
The signature
In the expert-verified and human-led models, the report is signed by Security Brigade as the empanelled firm that delivered the engagement.
The boundary
What this page claims, and what it does not
Compliance copy is where a vendor is most tempted to round a fact up. These are the four places this one deliberately stops.
| The position | |
|---|---|
| Whose instrument it is | The empanelment is Security Brigade’s. The B-52 platform holds no certification of its own, and nothing on this site says otherwise. |
| Mapping, not issuing | Findings are mapped to the controls an instrument names. Certification and attestation are issued by certification bodies and auditors appointed for that purpose, which is separate work from testing. |
| Scoped to the instrument that carries it | The requirement for empanelled delivery is named above per instrument, because those instruments are not interchangeable. A claim scoped to the wrong one is the commonest error on this subject and it is one this estate has made and corrected. |
| Your obligation is yours to confirm | Which instrument applies to your entity, and what it requires of you, is a determination for you and your advisers. What is stated here is what Security Brigade holds and what each delivery model produces. |
Whose instrument it is
- The position
- The empanelment is Security Brigade’s. The B-52 platform holds no certification of its own, and nothing on this site says otherwise.
Mapping, not issuing
- The position
- Findings are mapped to the controls an instrument names. Certification and attestation are issued by certification bodies and auditors appointed for that purpose, which is separate work from testing.
Scoped to the instrument that carries it
- The position
- The requirement for empanelled delivery is named above per instrument, because those instruments are not interchangeable. A claim scoped to the wrong one is the commonest error on this subject and it is one this estate has made and corrected.
Your obligation is yours to confirm
- The position
- Which instrument applies to your entity, and what it requires of you, is a determination for you and your advisers. What is stated here is what Security Brigade holds and what each delivery model produces.
Where to go next
If the filing is under SEBI CSCRF
The CSCRF page sets out the four cadences the framework keeps separate — VAPT, cyber audit, red teaming and threat hunting — because conflating them is the most frequent mistake made against that framework, and it changes what you are obliged to produce and when. Where the filing is under the RBI Directions instead, the relevant paragraphs and their cadences are on the RBI page. Both are linked below.
Other frameworks
Scope it with the delivery model the filing needs
Where the report leaves your organisation, start from the expert-verified model. A scoping call settles which instrument you are filing under and what the engagement has to cover.